首页> 外文会议>2012 IEEE Eighth World Congress on Services >Technical Analysis of Countermeasures against Attack on XML Encryption -- or -- Just Another Motivation for Authenticated Encryption
【24h】

Technical Analysis of Countermeasures against Attack on XML Encryption -- or -- Just Another Motivation for Authenticated Encryption

机译:防止XML加密攻击对策的技术分析-或-认证加密的另一个动机。

获取原文
获取原文并翻译 | 示例

摘要

At CCS'11 a new chosen-ciphertext attack on XML Encryption has been presented. This attack is of high relevance, since it allows one to decrypt arbitrary encrypted XML payload by issuing 14 server requests per byte on average. In this paper we discuss several countermeasures against this attack, which have been considered by different framework developers for different scenarios. We analyze the scenarios and show why these countermeasures do not work. Thereby, we motivate for the application of authenticated encryption in the XML Encryption specification.
机译:在CCS'11上,提出了一种针对XML加密的新的选择密文攻击。这种攻击具有很高的相关性,因为它允许平均每个字节发出14个服务器请求来解密任意加密的XML有效负载。在本文中,我们讨论了针对这种攻击的几种对策,不同的框架开发人员已针对不同的场景考虑了这些对策。我们分析了这些情况,并说明了为什么这些对策无效。因此,我们激励在XML加密规范中应用认证加密。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号